SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-55805

MEDIUM · CVSS 5.4 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-08-25 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Drupal core is vulnerable to a Stored Cross-site Scripting (XSS) attack due to improper input neutralization during web page generation, affecting multiple versions from 0.0.0 to 10.6.13 and various 11.x releases. This vulnerability could allow attackers to inject malicious scripts that execute in the context of users' browsers, potentially leading to data theft or session hijacking. Organizations using affected Drupal versions should prioritize remediation to protect user data and maintain application integrity.

CVE
CVE-2026-55805
Severity
MEDIUM
CVSS
5.4
EPSS
0.13%

Original NVD Description

Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Stored XSS. This issue affects Drupal core versions: from 0.0.0 to 10.6.13, from 11.3.0 to 11.3.14, from 11.4.0 to 11.4.4, from 0.0.0 to 11.0.*, from 0.0.0 to 11.1.*, from 0.0.0 to 11.2.*.